Skip to content

M0.13: make verified deployment runtime-neutral - #16

Merged
pgousdal merged 7 commits into
mainfrom
work/m0.13-runtime-neutral-verification
Sep 5, 2026
Merged

pgousdal merged 7 commits into
mainfrom
work/m0.13-runtime-neutral-verification

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Implements M0.13 runtime-neutral verification on top of the M0.11/M0.12 trust path.

Changes:

  • replace Docker Buildx digest resolution in scripts/verify-release.sh with Skopeo;
  • keep exact Cosign certificate identity and GitHub Actions OIDC issuer verification;
  • add RUNTIME=auto|docker|podman for post-verification pulls;
  • keep stdout machine-readable as the immutable verified image ref only;
  • remove Docker as a requirement for verified Quadlet rendering;
  • update deployment verification/enforcement workflows to use Skopeo;
  • add real CI qualification for both Docker and Podman pull paths plus a fail-closed wrong-issuer test;
  • document the M0.13 trust path and acceptance criteria.

The signed v0.2.3 release remains the immutable qualification target; no tag is moved or rewritten.

@pgousdal
pgousdal merged commit 4d5e1e7 into main Sep 5, 2026
17 checks passed
@pgousdal
pgousdal deleted the work/m0.13-runtime-neutral-verification branch September 5, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant